feat(pilot): capture existing Product access without repaying - #220
Merged
Merged
Conversation
✅ Deploy Preview for muzinga canceled.
|
knzeng-e
marked this pull request as ready for review
September 28, 2026 09:13
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0e0ad673eb
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
An operator can open an already-paid Classic track in a candidate-bound Product capture and export fresh entitlement/key evidence without paying again. The browser panel and CLI now require the key release to follow a read-back for the matching account, chain, runtime and content hash.
Issue and context
Refs #158. Scope: W13 pilot release; handoff: W13 evidence.
PR #219 made native payment recovery durable. W13's next live step is to reuse an existing entitlement, but normal playback of an existing purchase did not produce a payment read-back event. Operators could obtain a key without being able to export the corresponding fresh access read. Starting another payment to fill that gap would be unnecessary.
Starting dev:
9c25093d7508e643258fd3a66b576a8cea312707, with all Dev Quality Gates passing. The historicalfeat/pilot-releasebranch belongs to another worktree, so this slice usesfeat/pilot-access-readback.Architecture and key concepts
useCatalogcalls a small read-only collector on explicit Classic selection in Product mode. The collector accepts only thehasPaidandcanAccessread port, never a payment writer. It runs only inside an explicitly bound capture matching the current SHA/app version, then checks that the account, selection and capture are still current before publishing.The existing bounded session evidence journal gains an allowlisted
access-readbackevent. This is current entitlement evidence, not a transaction receipt: it contains no transaction hash, amount, signature or key. Payment events remain separate. The CLI computes its own gates from event facts instead of trusting the browser summary.How it works
hasPaidandcanAccess, then follow the normal protected-key request.Design decisions and tradeoffs
Security, failure, and operations
Runtime/API access checks remain authoritative. Evidence never grants access. RPC errors produce unknown results; stale account, track or candidate results are discarded. Cross-runtime, cross-chain and pre-read key events cannot complete the access/key journey, and a latest key denial/error remains visible.
Capture remains bounded, session-local and explicitly activated. The allowlist excludes secrets, but diagnostic exports contain account/release identifiers: keep them private and separate from aggregate pilot evidence, and reset the capture after use. The runbooks document this boundary.
No contract, deployment, secret, hosted configuration or payment-rail change. CASH remains non-executable; no PVM migration. Rollback is the ordinary application-code rollback, with no storage migration.
Review guide
Suggested order
web/src/features/productHost/productAccessReadback.tsand its tests: opt-in capture, read-only authority, stale-result rejection.web/src/hooks/useCatalog.ts: explicit selection trigger before key delivery.productCdmHostSmokeEvidence.tsand its tests: allowlisted event, truthful separate gates, matching key identity.web/scripts/product-devnet-journey-harness.mjsand its tests: independent CLI verification and blocked write gates.Verify carefully
Validation
Tested implementation:
8ac508037413776681ca5c477a5a214d474428d6(the focused unit/CLI/browser checks ran on the identical source before commit).e2e/classic-unlock.spec.tsnpx tsc -b,npm run lint, changed-file Prettier checknpm run buildVITE_DOTIFY_RUNTIME_ADAPTER=product-cdm VITE_DOTIFY_DEBUG_PANEL=true npm run build:product-devnet:frozengit diff --checksmoke:pilot-releaseon implementation SHAKnown limitations and follow-ups
This is W13 capture tooling, not W13 acceptance. No physical Product host/device session, payment, publication, rollback rehearsal or consented pilot was performed. After review, an authorized candidate publication and real existing-entitlement/key/room capture are still required. Signing/value forwarding needs separately authorized evidence; another payment is not required merely to validate existing access. Issue #158 stays open.
Metadata checklist
Dotify sprints)